Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-4680

Опубликовано: 06 нояб. 2023
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without convergent encryption. Introduced in 1.6.0 and fixed in 1.14.3, 1.13.7, and 1.12.11.

A flaw was found in HashiCorp Vault and Vault Enterprise, where the transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using the transit secrets engine without convergent encryption.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Openshift Container Storage 4ocs4/cephcsi-rhel8Out of support scope
Red Hat Openshift Container Storage 4ocs4/mcg-rhel8-operatorOut of support scope
Red Hat Openshift Container Storage 4ocs4/ocs-must-gather-rhel8Out of support scope
Red Hat Openshift Container Storage 4ocs4/ocs-rhel8-operatorOut of support scope
Red Hat Openshift Container Storage 4ocs4/rook-ceph-rhel8-operatorOut of support scope
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel9Out of support scope
Red Hat Openshift Data Foundation 4odf4/mcg-cli-rhel9Out of support scope
Red Hat Openshift Data Foundation 4odf4/mcg-rhel9-operatorOut of support scope
Red Hat Openshift Data Foundation 4odf4/ocs-metrics-exporter-rhel9Out of support scope
Red Hat Openshift Data Foundation 4odf4/ocs-must-gather-rhel8Out of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2306745vault: HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault

EPSS

Процентиль: 80%
0.01521
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
nvd
почти 2 года назад

HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without convergent encryption. Introduced in 1.6.0 and fixed in 1.14.3, 1.13.7, and 1.12.11.

CVSS3: 6.8
redos
8 месяцев назад

Уязвимость vault

CVSS3: 6.8
github
почти 2 года назад

HashiCorp Vault Improper Input Validation vulnerability

CVSS3: 6.8
fstec
почти 2 года назад

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, связанная с неправильной проверкой входных данных, позволяющая нарушителю задавать произвольные случайные значения (нонсы) при отключённой конвергентной криптографии

EPSS

Процентиль: 80%
0.01521
Низкий

6.8 Medium

CVSS3

Уязвимость CVE-2023-4680